CVE Tools

Netweaver

102 CVEs tracked. 3 of them are in CISA KEV.

This hub aggregates every CVE we track for Netweaver, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Netweaver CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Netweaver CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-051
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 102 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1212%
  • High2424%
  • Medium6463%
  • Low22%

Latest CVEs

The 15 most recently published vulnerabilities affecting Netweaver.

  1. CVE-2026-23685Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)4.4
  2. CVE-2025-42968Missing Authorization check in SAP NetWeaver (RFC enabled function module)5.0
  3. CVE-2025-42999Insecure Deserialization in SAP NetWeaver (Visual Composer development server)9.1
  4. CVE-2025-31324Missing Authorization check in SAP NetWeaver (Visual Composer development server)10.0
  5. CVE-2024-27898Server-Side Request Forgery in SAP NetWeaver5.3
  6. CVE-2024-25644Information Disclosure vulnerability in NetWeaver (WSRM)5.3
  7. CVE-2024-22124Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager4.1
  8. CVE-2023-41367Missing Authentication check in SAP NetWeaver (Guided Procedures)5.3
  9. CVE-2023-36922OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)9.1
  10. CVE-2023-33985Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal6.1
  11. CVE-2023-33984Cross-Site Scripting (XSS) vulnerability in NetWeaver (Design Time Repository)6.4
  12. CVE-2023-32114Denial of Service in SAP NetWeaver2.7
  13. CVE-2023-29186Directory/Path Traversal vulnerability in SAP NetWeaver.8.7
  14. CVE-2023-27499Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML6.1
  15. CVE-2023-0021Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store